packagist in2code/powermail 10.9.3
[!!!][RELEASE] 10.9.3 Security Release

latest releases: 13.2.1, 12.6.1
6 hours ago

Security fix - please update ASAP

This release contains two security fixes.

  1. [!!!] Fluid viewhelper injection in FE

It was possible to use arbitrary viewhelpers in frontend files, like sender name or sender email. This is now prevented via a whitelist in the extension configuration. If you use other viewhelpers, you need to whitelist them in the extension configuration.

  1. Enforce page access in the backend module

With non numeric uid values, it was possible to gain access to mails on pages where an editor had no access to. This is now mitigated via an additional access check.

Full Changelog: 10.9.2...10.9.3

Don't miss a new powermail release

NewReleases is sending notifications on new releases.